Critical severity9.1NVD Advisory· Published Jul 12, 2022· Updated Jun 17, 2026
CVE-2021-44222
CVE-2021-44222
Description
A vulnerability has been identified in SIMATIC eaSie Core Package (All versions < V22.00). The underlying MQTT service of affected systems does not perform authentication in the default configuration. This could allow an unauthenticated remote attacker to send arbitrary messages to the service and thereby issue arbitrary requests in the affected system.
Affected products
3< V22.00+ 2 more
- (no CPE)range: < V22.00
- cpe:2.3:a:siemens:simatic_easie_core_package:*:*:*:*:*:*:*:*range: <22.00
- (no CPE)range: All versions < V22.00
Patches
Vulnerability mechanics
References
1- cert-portal.siemens.com/productcert/pdf/ssa-580125.pdfnvdPatchVendor Advisory
News mentions
0No linked articles in our index yet.